A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV).
Metrics
Affected Vendors & Products
References
History
Sat, 30 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 28 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GPAC MP4Box Null Pointer Dereference Causing Crash |
Thu, 28 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 28 May 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gpac
Gpac mp4box |
|
| Vendors & Products |
Gpac
Gpac mp4box |
Wed, 27 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | GPAC MP4Box Null Pointer Dereference Causing Crash | |
| Weaknesses | CWE-476 |
Wed, 27 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media_map_esd then calls strlen() on a NULL pointer, triggering a crash (ASan SEGV). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-27T00:00:00.000Z
Updated: 2026-05-30T14:32:36.802Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70116
Updated: 2026-05-30T14:32:36.802Z
Status : Received
Published: 2026-05-27T17:16:29.187
Modified: 2026-05-30T15:16:14.080
Link: CVE-2025-70116
No data.